Artificial Intelligence

Code Execution Flaws Haunt NVIDIA ChatRTX for Windows

Artificial intelligence computing giant NVIDIA patches flaws in ChatRTX for Windows and warns of code execution and data tampering risks.

Artificial intelligence computing giant NVIDIA patches flaws in ChatRTX for Windows and warns of code execution and data tampering risks.

Artificial intelligence computing giant NVIDIA on Wednesday pushed out urgent patches for a pair of software flaws in its ChatRTX for Windows app alongside a warning that users are at risk of code execution and data tampering attacks.

According to an advisory from NVIDIA, the flaws carry a ‘high-risk’ rating and could be exploited to launch harmful code via cross-site-scripting attacks.

The security defects, flagged as CVE‑2024‑0082 and CVE-2024-0083, affect ChatRTX for Windows 0.2 and prior versions.

The raw details:

  • CVE‑2024‑0082 — NVIDIA ChatRTX for Windows contains a vulnerability in the UI, where an attacker can cause improper privilege management by sending open file requests to the application. A successful exploit of this vulnerability might lead to local escalation of privileges, information disclosure, and data tampering. CVSS severity score 8.2/10.
  • CVE-2024-0083 — NVIDIA ChatRTX for Windows contains a vulnerability in the UI, where an attacker can cause a cross-site scripting error by network by running malicious scripts in users’ browsers. A successful exploit of this vulnerability might lead to code execution, denial of service, and information disclosure. CVSS severity score 6.5/10

The NVIDIA ChatRTX app is used by developers and AI enthusiasts to connect PC LLMs to their own data using a popular technique known as retrieval-augmented generation (RAG).

Related: The Chaos (and Cost) of the Lapsus$ Hacking Carnage

Related: Dymium Snags $7M to Build Data Security Platform with Secure AI Chat 

Advertisement. Scroll to continue reading.

Related: Microsoft Catches APTs Using ChatGPT for Vuln Research

Related: NVIDIA Patches Code Execution Vulnerabilities in Graphics Driver

Related Content

Artificial Intelligence

The Nvidia-led coalition aims to give defenders more open tools for testing, auditing and protecting AI models and agents.

Artificial Intelligence

AgentForger allows an attacker to create, insert and remotely control an invisible autonomous AI agent inside a victim organization.

Artificial Intelligence

Advanced Account Security provides stronger login methods, more secure account recovery, shorter sessions, and training exclusion.

Artificial Intelligence

Marketed as ChatGPT enhancement and productivity tools, the extensions allow the threat actor to access the victim's ChatGPT data.

Artificial Intelligence

Radware bypassed ChatGPT’s protections to exfiltrate user data and implant a persistent logic into the agent’s long-term memory.

Artificial Intelligence

A researcher found a way to exploit an SSRF vulnerability related to custom GPTs to obtain an Azure access token. 

Vulnerabilities

Intel, AMD and Nvidia have published security advisories describing vulnerabilities found recently in their products.

Artificial Intelligence

Tenable researchers discovered seven vulnerabilities, including ones affecting the latest GPT model.

Copyright © 2026 SecurityWeek ®, a Wired Business Media Publication. All Rights Reserved.

Exit mobile version